A data engineer needs to unload a large table to an external stage in Parquet format. The table contains a column with sensitive data that must be masked in the unloaded files. The engineer wants to use a secure view that applies a masking policy, and then unload from that view. Which statement accurately describes the behavior when unloading from a secure view?
Snowflake supports unloading from secure views, and the policies (masking, row access) defined in the view are enforced during the unload. This allows sensitive data to be masked in the output files. The unload operation executes the view's query, so the policies are applied. This is the correct and secure approach for the scenario.
Why this answer
COPY INTO <location> supports unloading from secure views, and the secure view's definition, including masking and row access policies, is enforced during the unload. This means sensitive columns can be masked in the output files. The other options either deny support, claim masking is bypassed, or impose unnecessary role requirements.
The correct behavior is that policies are applied, ensuring data security.
Exam trap
The trap here is assuming that unloading from a secure view bypasses masking policies, when in fact the policies are enforced.